Compliance ControlsAmazon RDS
RDS Aurora cluster parameter groups should require TLS for client connections
Implementation
Choose the approach that matches how you manage Terraform.
Use the compliance.tf module to enforce this control by default. See get started with compliance.tf.
This control is enforced automatically with Compliance.tf modules. Start free trial
If you use terraform-aws-modules/rds-aurora/aws, set the right module inputs for this control. You can later migrate to the compliance.tf module with minimal changes because it is compatible by design.
module "rds_aurora" {
source = "terraform-aws-modules/rds-aurora/aws"
version = ">=10.0.0,<11.0.0"
create_db_subnet_group = true
create_security_group = true
engine = "aurora-mysql"
engine_version = "8.0.mysql_aurora.3.08.0"
manage_master_user_password = true
master_username = "root"
name = "abc123"
port = 3307
skip_final_snapshot = true
subnets = ["subnet-12345678", "subnet-12345678"]
vpc_id = "vpc-12345678"
}Use AWS provider resources directly. See docs for the resources involved: aws_rds_cluster_parameter_group.
resource "aws_rds_cluster_parameter_group" "this" {
family = "aurora-mysql8.0"
name = "example-abc123"
parameter {
name = "require_secure_transport"
value = "ON"
}
}Tool mappings
Use these identifiers to cross-reference this control across tools, reports, and evidence.
- Compliance.tf Control:
rds_db_cluster_parameter_group_encryption_in_transit_enabled